Data Processing Addendum
How JadeOps LLC handles the business data restaurant operators put into JadeOps.
Jump to section(12)
This addendum is between JadeOps LLC and Customer. It sets out how we process Your Data on Customer’s behalf. Questions? Email support@jadeops.io — a person reads every message.
When this addendum applies
This Data Processing Addendum (“DPA”) applies whenever Customer uses the Services. It forms part of the Terms of Service. Capitalized terms not defined here, such as Services, Customer, Owner, Authorized Users, and Your Data, have the meanings in the Terms.
Roles
For Your Data, Customer is the controller (a “business” under the California Consumer Privacy Act) and JadeOps LLC is the processor (a “service provider”). Our Privacy Policy covers the account and usage information we control ourselves.
Scope and purpose
We process Your Data only to provide, secure, and support the Services. Customer’s documented instructions are the Terms, this DPA, and Customer’s use of the features and settings in the Services, such as the “AI features” switch.
Service-provider commitments
We will not:
- sell or share Your Data;
- retain, use, or disclose Your Data for any purpose other than providing the Services, or outside our direct business relationship with Customer; or
- combine Your Data with personal information we receive from others, except as the CCPA and its regulations permit.
We will comply with the CCPA as it applies to service providers and will notify Customer if we can no longer meet these obligations. Customer may take reasonable steps to stop and fix any unauthorized use of Your Data.
Confidentiality of personnel
Everyone at JadeOps who can access Your Data is bound by confidentiality obligations. We log each time an Admin opens customer information in our administration tools.
Security measures
- Encryption in transit and at rest, managed by our providers.
- Store-level access controls: Managers see only the stores they are assigned to.
- Passwords stored only in hashed form.
- Rate limiting on sign-in and other sensitive actions.
- Change history on key records, showing the record before and after and who changed it.
- A log of each time an Admin opens customer information in our administration tools. A small number of JadeOps staff can also reach the database directly for support and security; that direct access is not separately logged.
- Error monitoring.
Subprocessors
Customer authorizes us to use these subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, sign-in, file storage | United States |
| Vercel | Hosting, Web Analytics, Speed Insights | United States |
| Stripe | Payments | United States |
| PostHog | Product analytics, session recording | United States |
| Sentry | Error monitoring | United States |
| SMTP2GO | Email delivery | New Zealand (company); servers worldwide |
| Anthropic | AI Advisor and receipt scanning | United States |
| Optional sign-in | United States/global |
We update this list before a new subprocessor starts processing Your Data. Each subprocessor is bound by data-protection terms that cover the processing it performs for us.
Help with rights requests
If an individual asks us to access, correct, delete, or copy Your Data, we will refer them to Customer where we can. Taking into account the nature of the processing, we will give Customer reasonable help to respond to requests it receives.
Breach notice
If we confirm unauthorized access to Your Data, we will notify affected Owners without undue delay and within 72 hours after confirming it. We will share what we know about the incident and the steps we are taking, and update Owners as we learn more.
Return and deletion
Export, return, and deletion of Your Data work as described in section 4 (Your Data) of the Terms.
Audits
Once per year, on reasonable written request to support@jadeops.io, we will answer a security questionnaire and provide the security documentation we have available. We do not offer on-site audits.
Order of precedence
Subject to any signed order form, this DPA controls over the Terms on data-protection matters. Each party’s liability under this DPA is subject to the limitation of liability in section 14 of the Terms.